The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get IPS Policy Details

Prev Next

This URL gets the policy details (including attack set and response actions) for the specific IPS policy.

Resource URL

GET /ipspolicy/<policy_id>

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
policy_id IPS policy id Number Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
PolicyDescriptor Baseline IPS policy details Object

Details of PolicyDescriptor:

Field Name Description Data Type
PolicyName Baseline IPS policy name String
Description Policy description String
IsVisibleToChildren Is policy visible to child domain Boolean
InboundRuleSet Inbound policy rule set String
OutboundRuleSet Outbound policy rule set String
AttackCategory Attack category Object
OutboundAttackCategory Outbound attack category Object
DosPolicy DoS policy Object
DosResponseSensitivityLevel DoS response sensitivity level Number
IsEditable Is policy editable Boolean
Timestamp Time stamp at which the policy was added String
VersionNum Policy version number Number
IsLightWeightPolicy Is light weight policy configured Boolean

Details of object in AttackCategory:

Field Name Description Data Type
ExpolitAttackList List of exploit attacks Array

Details of object in ExpolitAttackList:

Field Name Description Data Type
attackName Attack name String
nspId NSP id of the attack String
severity Attack severity, number between 0 & 9 Number
isSeverityCustomized Is attack severity customized Boolean
isEnabled Is attack enabled Boolean
isAlertCustomized Is alert customized Boolean
isRecommendedForSmartBlocking Is attack recommended for smart blocking Boolean
AttackResponse Attack response Object
notification Notifications configured Object
protocolList List of protocols Array
applicationsImpactedList List of applications impacted Array
attackVector List of attack vectors Array
benignTriggerProbability Attack benign trigger probability String
target Attack target, can be "Server" or "Client" String
blockingType Blocking type, can be "Attack Packet" String
subCategory Attack sub category String
direction Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" String
isAttackCustomized Is attack customized Boolean

Details of object in AttackResponse:

Field Name Description Data Type
TCPReset TCP reset option, can be “DISABLED” / “SOURCE” / “DESTINATION” / “BOTH” String
isTCPResetCustomized Is TCP reset customized Boolean
isICMPSend Send ICMP host unreachable to Source Boolean
isICMPSendCustomized Send ICMP host unreachable to Source customized Boolean
mcafeeNACNotification NAC notification configured, can be “DISABLED” / “ALL_HOSTS” / “MCAFEE_NAC_UNMANAGED_HOSTS” String
isMcafeeNACNotificationEnabled Is NAC notification enabled Boolean
isQuarantineCustomized Is quarantine customized Boolean
isRemediateEnabled Is remediate enabled Boolean
blockingOption Blocking option configured, can be “DISABLE” / “ENABLE” / “ENABLE_SMART_BLOCKING” String
isBlockingOptionCustomized Is blocking option customized Boolean
isCapturedPrior Should application data be captured prior to attack Boolean
isCapturedPriorCustomized Should application data be captured prior to attack customized Boolean
action Action to be taken on attack, can be “DO_NOTHING” / “SEND_ALERT_AND_LOG_PACKETS” / “SEND_ALERT_ONLY” String
isLogCustomized Is logging customized Boolean
flow Customixe flow, can be “SINGLE_FLOW” / “FORENSIC_ANALYSIS” String
isFlowCustomized Customize flow type Boolean
isNbytesCustomized Is logging N bytes in each packet customized Boolean
numberOfBytesInEachPacket Number of bytes to be logged in each packet Object
loggingDuration Packet logging duration Object
TimeStamp Time stamp String

Details of object in numberOfBytesInEachPacket (Can be either of the below mentioned):

Field Name Description Data Type
LogEntirePacket Log entire packet Object
CaptureNBytes Capture N bytes Object

Details of object in CaptureNBytes:

Field Name Description Data Type
NumberOfBytes Number of bytes to log Number

Details of object in loggingDuration (Can be either of the below mentioned):

Field Name Description Data Type
AttackPacketOnly Log attack packet only Object
CaptureNPackets Capture N packets Object
CaptureTimeDuration Capture for a time duration Object
RestOfFlow Capture rest of flow Object

Details of object in CaptureNPackets:

Field Name Description Data Type
npackets Log n packets Number

Details of object in CaptureTimeDuration:

Field Name Description Data Type
time Capture time String
timeUnit Time unit, can be "SECONDS" / "MINUTES" / "HOURS" / "DAYS" String

Details of object in notification:

Field Name Description Data Type
isEmail Is notification configured through email Boolean
isPager Is notification configured through pager Boolean
isScript Is notification configured through script Boolean
isAutoAck Is notification configured through auto ack Boolean
isSnmp Is notification configured through SNMP Boolean
isSyslog Is notification configured through syslog Boolean
isEmailCustomized Is notification through email customized Boolean
isPagerCustomized Is notification through pager customized Boolean
isScriptCustomized Is notification through script customized Boolean
isAutoAckCustomized Is notification through auto ack customized Boolean
isSnmpCustomized Is notification through SNMP customized Boolean
isSyslogCustomized Is notification through syslog customized Boolean

Details of object in DosPolicy:

Field Name Description Data Type
LearningAttack List of learning attacks Array
ThresholdAttack List of threshold attacks Array
TimeStamp Time stamp String

Details of object in LearningAttack:

Field Name Description Data Type
attackName Attack name String
nspId NSP ID of the attack String
isSeverityCustomized Is attack severity customized Boolean
severity Attack severity, number between 0 & 9 Number
isBlockingSettingCustomized Is blocking customized Boolean
isDropPacket Drop DoS attack packets of this attack type when detected Boolean
isAlertCustomized Is alert customized Boolean
isSendAlertToManager Is alert notification to be sent to Manager configured String
timeStamp Time stamp String
direction Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" String
notification Notification to be sent via Object
isAttackCustomized Is DoS learning attack customized Boolean

Details of object in ThresholdAttack:

Field Name Description Data Type
attackName Attack name String
nspId NSP id of the attack String
isSeverityCustomized Is attack severity customized Boolean
severity Attack severity, number between 0 & 9 Number
isThresholdValueCustomized Is threshold value customized Boolean
isThresholdDurationCustomized is threshold duration customized Boolean
ThresholdValue Threshold values Number
ThresholdDuration Threshold Interval (Seconds) Number
isAlertCustomized Is alert customized Boolean
isSendAlertToManager Is alert notification to be sent to Manager configured String
TimeStamp Time stamp String
Notification Notification to be sent Object
direction Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" String
isAttackCustomized Is DoS threshold attack customized Boolean

Example

Request

GET https://%3CNSM_IP%3E/sdkapi/ipspolicy/0

Response

{
   "PolicyDescriptor":
   {
       "PolicyName": "IpsPolicy",
       "Description": "To test the IPS policy",
       "IsVisibleToChildren": true,
       "InboundRuleSet": "TestIPS",
       "OutboundRuleSet": "Null",
       "AttackCategory":
       {
           "ExpolitAttackList":
           [
               {
                   "attackName": "FTP: VMware Flaw in NAT Function",
                   "nspId": "0x4050b400",
                   "severity": 7,
                   "isSeverityCustomized": false,
                   "isEnabled": true,
                   "isAlertCustomized": false,
                   "isRecommendedForSmartBlocking": false,
                   "AttackResponse":
                   {
                       "TCPReset": "DISABLED",
                       "isTcpResetCustomized": false,
                       "isICMPSend": false,
                       "isICMPSendCustomized": false,
                       "mcAfeeNACNotification": "DISABLED",
                       "isMcAfeeNACNotificationEnabled": false,
                       "isQuarantineCustomized": false,
                       "isRemediateEnabled": false,
                       "blockingOption": "DISABLE",
                       "isBlockingOptionCustomized": false,
                       "isCapturedPrior": true,
                       "isCapturedPriorCustomized": false,
                       "action": "SEND_ALERT_ONLY",
                       "isLogCustomized": false,
                       "isFlowCustomized": false,
                       "isNbytesCustomized": false,
                       "numberOfBytesInEachPacket":
                       {
                           "LogEntirePacket":
                           {
                           }
                       }
                   },
                   "notification":
                   {
                       "isEmail": false,
                       "isPager": false,
                       "isScript": false,
                       "isAutoAck": false,
                       "isSnmp": false,
                       "isSyslog": false,
                       "isEmailCustomized": false,
                       "isPagerCustomized": false,
                       "isScriptCustomized": false,
                       "isAutoAckCustomized": false,
                       "isSnmpCustomized": false,
                       "isSyslogCustomized": false
                   },
                   "protocolList":
                   [
                       "ftp"
                   ],
                   "benignTriggerProbability": "1 (Low)",
                   "blockingType": "attack-packet",
                   "subCategory": "code-execution",
                   "direction": "INBOUND",
                   "isAttackCustomized": false
               }
           ]
       },
       "OutboundAttackCategory":
       {
       },
       "DosPolicy":
       {
           "LearningAttack":
           [
               {
                   "attackName": "TCP Control Segment Anomaly",
                   "nspId": "0x40008700",
                   "isSeverityCustomized": false,
                   "severity": 7,
                   "isBlockingSettingCustomized": false,
                   "isDropPacket": false,
                   "IsAlertCustomized": false,
                   "isSendAlertToManager": true,
                   "direction": "BOTH",
                   "notification":
                   {
                       "isEmail": false,
                       "isPager": false,
                       "isScript": false,
                       "isAutoAck": false,
                       "isSnmp": false,
                       "isSyslog": false,
                       "isEmailCustomized": false,
                       "isPagerCustomized": false,
                       "isScriptCustomized": false,
                       "isAutoAckCustomized": false,
                       "isSnmpCustomized": false,
                       "isSyslogCustomized": false
                   },
                   "isAttackCustomized": false
               }
           ],
           "ThresholdAttack":
           [
               {
                   "attackName": "Too Many Inbound TCP SYNs",
                   "nspId": "0x40008c00",
                   "isSeverityCustomized": false,
                   "severity": 6,
                   "isThresholdValueCustomized": false,
                   "isThresholdDurationCustomized": false,
                   "ThresholdValue": 2000,
                   "ThresholdDuration": 5,
                   "isAlertCustomized": false,
                   "isSendAlertToManager": false,
                   "Notification":
                   {
                       "isEmail": false,
                       "isPager": false,
                       "isScript": false,
                       "isAutoAck": false,
                       "isSnmp": false,
                       "isSyslog": false,
                       "isEmailCustomized": false,
                       "isPagerCustomized": false,
                       "isScriptCustomized": false,
                       "isAutoAckCustomized": false,
                       "isSnmpCustomized": false,
                       "isSyslogCustomized": false
                   },
                   "direction": "INBOUND",
                   "isAttackCustomized": false
               }
           ],
           "TimeStamp": "2012-06-20 18:44:55.000"
       },
       "DosResponseSensitivityLevel": 0,
       "IsEditable": false,
       "Timestamp": "2012-06-20 18:44:55.000",
       "VersionNum": 1,
       "IsLightWeightPolicy": false
   }
} 
 

Error Information

Following error code is returned by this URL:

S.No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1108 Invalid policy Id